CVE-2018-14664: XSS
A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.
References: https://projects.theforeman.org/issues/25169
Introduced in: https://projects.theforeman.org/issues/22855
Other sources
A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-14664?
CVE-2018-14664 is a stored cross-site scripting vulnerability found in Foreman versions 1.18.
How severe is CVE-2018-14664?
CVE-2018-14664 has a severity rating of 5.4, which is considered medium.
How does CVE-2018-14664 affect Foreman?
CVE-2018-14664 allows a user with permissions to edit the attribute used in the breadcrumbs bar to execute code on the client-side.
Which versions of Foreman are affected by CVE-2018-14664?
Foreman versions 1.18.0 up to, but excluding, 1.18.3 are affected by CVE-2018-14664.
How can I fix CVE-2018-14664?
To fix CVE-2018-14664, it is recommended to update to version 1.18.3 of Foreman.